VYPR
High severityNVD Advisory· Published Dec 5, 2023· Updated Aug 2, 2024

CVE-2023-49448

CVE-2023-49448

Description

JFinalCMS v5.0.0 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via admin/nav/delete.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

JFinalCMS v5.0.0 is vulnerable to CSRF via admin/nav/delete, allowing attackers to delete navigation items without authentication.

JFinalCMS v5.0.0 suffers from a Cross-Site Request Forgery (CSRF) vulnerability in the navigation management functionality. The flaw exists in the /admin/nav/delete endpoint, which performs deletion operations without implementing CSRF tokens or other anti-forgery protections [1][2]. An attacker can craft a malicious HTML page that automatically submits a POST request to delete a navigation item, leveraging the authenticated session of an unaware administrator.

To exploit this vulnerability, the attacker must trick an authenticated administrator into visiting a crafted webpage or clicking a malicious link. The attack requires no special privileges beyond the administrator's existing session, and the request is automatically executed if the victim is logged in to JFinalCMS. The provided proof-of-concept demonstrates a simple form submission that deletes a navigation entry with a given ID [2].

Successful exploitation allows an attacker to delete arbitrary navigation items defined in the CMS, potentially disrupting site structure and functionality. Since delete operations are performed without user confirmation, an attacker could silently remove critical navigation links. This could lead to denial of service or defacement of the admin interface.

As of publication, no official patch has been released for JFinalCMS v5.0.0, and the software may be end-of-life. Administrators are advised to implement additional CSRF protections, such as using anti-CSRF tokens or validating the origin header for sensitive actions. Alternatively, restricting access to the admin panel via network controls can reduce exposure [1].

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
com.jfinal:jfinalMaven
<= 5.0.0

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.